Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
How does Shodan grab RDP screenshots of Windows machines, post-Server 2003?

Hi folks,

Something I've been curious about is how Shodan manages to grab screenshots of unauthenticated Console sessions ("RDP Screenshots") on machines newer than Server 2003, and how I can do the same from my machine. On Server 2003 and older, you can use the -console flag with mstsc.exe (e.g. mstsc -v:(Hostname or IP Address) -console) to initiate this console session, and present a logon screen as if you were physically at the device, with no authentication needed.

However, this was removed in Server 2008 for obvious security reasons, and trying to use the -console flag to connect to a Server 2008 and later machine is ignored - you are prompted for authentication and if successful enter a standard RDP session.

Does anyone know how Shodan does it? Thanks in advance!

submitted by /u/BloodyGenius
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
If you pwn a server, how would you profit from it?

We're usually invested in learning how to get into a server, but... then what?

Of course if you'd have multiple pwns you'd be able to build up a decent botnet, but what about only one? Is it possible to capitalize on it and what would be more profitable?

General question to understand which types of threat analysis should be invested to try to identify traffic types.

submitted by /u/skully_kiddo
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video